Fun

Alex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiK

News Feed - 2024-05-15 05:05:19

Christopher Roark3 hours agoAlex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiKThe deployer account changed an Alex contract’s implementation address, and multiple tokens were subsequently drained from its bridge.887 Total views9 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAccording to a May 14 report from blockchain security platform CertiK, the Alex protocol bridge on the BNB Smart Chain network suffered $4.3 million in suspicious withdrawals just after its contract was suddenly upgraded.


Alex is a Bitcoin layer-2 protocol. According to its official website, it provides decentralized finance applications on Bitcoin. Its bridges are used to transfer assets from other networks, such as BNB Smart Chain and Ethereum, to its own network.


Blockchain data confirms that the Alex deployer account performed five identical upgrades to the “Bridge Endpoint” contract on BNB Smart Chain beginning at 3:56 pm UTC. Approximately $4.3 million worth of Binance-Pegged Bitcoin (BTC), USD Coin (USDC), and Sugar Kingdom Odyssey (SKO) were subsequently removed from the BNB Smart Chain side of the bridge.


Because the upgrade was performed by the protocol’s deployer account, CertiK labeled the event “a possible private key compromise.” Source: CertiK


The upgrade transaction changed the implementation address to one ending in 7058. The new implementation is unverified bytecode, making it unreadable to human beings.


About 48 minutes after these upgrades began, the proxy address for the bridge contract called an unverified function on an address ending in 4848E. This resulted in 16 BTC ($983,000 at current prices), 2.7 million SKO ($75,000) and $3.3 million worth of USDC at 4:44 pm, being moved into the address at 484E.


The attacker may also be attempting to drain funds on other networks. At 5:41 pm, just minutes after the suspicious upgrade on BNB Smart Chain, a similar series of Alex upgrades occurred on Ethereum. In this case, the deployer upgraded the “artist address” to an unverified contract. Immediately afterward, an account ending in 05ed attempted to make two withdrawals from the “team address.” These withdrawals failed, producing a “not owner” error.


The 05ed account had no history before May 10. It created one unverified contract on May 10 and two more on May 14, indicating that it may be under the control of a malicious user.


At the time of publication, the Alex team has not confirmed the exploit or commented on the incident.


The Alex bridge wasn’t the only protocol to face a potential exploit in May. On May 13, decentralized exchange Equalizer announced that it had lost more than 2,000 of its own tokens from an attacker who siphoned them away in small increments over several days. The Gnus.ai hack on May 6 also resulted in $1.27 million worth of losses.


Related:CertiK discovered $5M security flaw in Wormhole bridge on Aptos# Bitcoin# Blockchain# Ethereum# Hackers# Private Keys# Cybersecurity# Hacks# DeFi# Layer2Add reaction

News Feed

Crypto markets need ‘disinfectant,’ says SEC chair
Turner Wright2 hours agoCrypto markets need ‘disinfectant,’ says SEC chairGary Gensler implied many market participants preferred to “whittle away at the SEC’s disclosure regime” rather than register, despite c
100 Companies Fail to Obtain Crypto Licenses in Singapore Due to Tough Regulation
100 Companies Fail to Obtain Crypto Licenses in Singapore Due to Tough Regulation More than 100 companies that applied for a license to offer crypto services in Singapore have eith
Mt Gox Creditors Updated, Trustee Says Rehabilitation Custodian Is ‘Currently Preparing to Make Repayments’
Mt Gox Creditors Updated, Trustee Says Rehabilitation Custodian Is "Currently Preparing to Make Repayments" On August 31, 2022, the Mt Gox trustee Nobuaki Kobayashi explained in a
Worldcoin turns one: Looking back at a year of controversy and growth
Shiraz Jagati10 hours agoWorldcoin turns one: Looking back at a year of controversy and growthOne year in, Worldcoin’s vision of a universal digital identity system shows promise with millions of users.1248 Total views
Indian Parliament Committee Discusses Crypto Regulation With Industry Experts
Indian Parliament Committee Discusses Crypto Regulation With Industry Experts India’s parliamentary committee on finance has held a meeting with representatives from the cry
Deutsche Bank Reports €5.3 Billion in Net Loss for 2019 as It Counts the Cost of Restructuring
Deutsche Bank Reports €5.3 Billion in Net Loss for 2019 as It Counts the Cost of Restructuring A year of reorganization has left its mark on Germany’s leading financial i
Report: Cambodia Reaffirms Stance Against Unsanctioned Crypto-Related Activities
Report: Cambodia Reaffirms Stance Against Unsanctioned Crypto-Related Activities Cambodian authorities have reportedly said that no cryptocurrency company has been issued a busines
Bitcoin’s Average and Median-Sized Network Fees Rose 40% Higher in March
Bitcoin"s Average and Median-Sized Network Fees Rose 40% Higher in March In March 2023, Bitcoin’s average and median-sized fees jumped more than 40% higher after rising 122%
Overstock’s Venture Arm Invests $2 Million in Blockchain ID Firm
Blockchain-based identity firm Evernym has received a $2 million investment from Overstock subsidiary Medici Ventures, according to a release from the company. Medici Ventures pa
Nigeria to train 1,000 youths on AI, blockchain every year
Arijit Sarkar11 hours agoNigeria to train 1,000 youths on AI, blockchain every yearThe Nigerian government has launched an annual training program for 1,000 citizens in AI and blockchain to position Nigeria ahead of glob
After Empire’s Exit Scam, Darknet Market Patrons Scramble to Find Alternatives
After Empire"s Exit Scam, Darknet Market Patrons Scramble to Find AlternativesEver since the darknet market (DNM) Empire went under, DNM patrons have been scrambling to find reliabl
Former FTX CEO Sam Bankman-Fried Pleads Not Guilty to Criminal Charges, Bond Signees’ Names Remain Sealed 
Former FTX CEO Sam Bankman-Fried Pleads Not Guilty to Criminal Charges, Bond Signees" Names Remain Sealed  On Jan. 3, 2023, the former FTX CEO Sam Bankman-Fried (SBF) pleaded not